The good news is that being unprepared isn’t a permanent condition. Understanding where the gaps tend to appear is the first step toward closing them.
What Is Operational Due Diligence?
Operational due diligence is a formal evaluation process, typically conducted by investors, institutional clients, or regulators, that assesses whether a firm’s operational and cybersecurity infrastructure meets acceptable standards. It goes beyond a casual conversation about whether you have antivirus software or security awareness training. Reviewers want to see documentation, processes, and evidence that controls are active and understood across the organization.
In financial services, operational due diligence has long been standard practice. Hedge funds, private equity firms, and asset managers routinely face these reviews from allocators before capital is committed. But the practice is spreading. Law firms, accounting practices, family offices, and professional service organizations increasingly find themselves on the receiving end of a due diligence questionnaire, often for the first time.
The False Confidence Problem
Most firms that haven’t been through a formal review believe, in good faith, that they’re reasonably well-protected. They’ve invested in security tools. They use multi-factor authentication. They have someone keeping an eye on things. That’s a solid start, but it misses the point of what operational due diligence is actually measuring.
Tools Are Not the Same as Outcomes
The distinction reviewers care about is between having a tool and being able to demonstrate what that tool does, how it’s configured, who monitors its alerts, and what happens when something goes wrong. A firm can have best-in-class endpoint protection and still fail an operational due diligence review if no one can articulate how it works or produce a report showing it’s active.
This is where false confidence becomes a real liability. The assumption that “we have good security” often hasn’t been tested against the specific, structured questions that appear in the cybersecurity portion of a due diligence questionnaire. Until it is, firms are essentially estimating their own readiness.
Where Operational Due Diligence Reveals the Gaps
When firms go through their first serious review, the failures tend to cluster around a few predictable areas. These aren’t always about missing tools. More often, they’re about missing infrastructure around the tools.
Documentation Is Incomplete or Outdated
Reviewers consistently ask for written policies: an information security policy, an incident response plan, a business continuity and disaster recovery plan. Many firms have some version of these documents, but they were written years ago, haven’t been updated, and don’t reflect how the organization actually operates today. Cybersecurity documentation that doesn’t match current practice is arguably worse than no documentation at all, because it raises questions about accuracy and ownership.
There’s a newer gap that’s appearing with increasing frequency in operational due diligence reviews: AI usage and governance . Many firms have adopted AI tools across their workflows without updating their policies to reflect that reality. DDQs are now asking whether firms have an AI acceptable use policy, and reviewers want to know specifically what data is being entered into large language models and how that’s being controlled. A firm that can’t answer those questions, or whose written policies predate AI adoption entirely, raises an immediate red flag. Building and maintaining an AI acceptable use policy, along with the security controls to back it up, has become part of what a complete and current documentation set looks like.
Answers Are Inconsistent Across the Team
One of the more common and damaging problems in live ODD interviews is when different people at the same firm give different answers to the same question. The CFO describes the incident response process one way; the IT contact describes it differently. The investor notices. Inconsistency signals that the security program isn’t truly embedded in the organization, it’s just a set of tools that someone manages without broader awareness.
No One Owns the DDQ Process
Completing a due diligence questionnaire is time-consuming, detail-intensive work. At most firms, there’s no designated owner for this process. When a DDQ arrives, it gets passed around. Answers are assembled from whoever responds to emails fastest. The result is incomplete responses, missed questions, and answers that haven’t been reviewed for accuracy against actual controls. That kind of response doesn’t build confidence with a sophisticated reviewer. This is where a cybersecurity partner becomes valuable.
Policy and Reality Don’t Match
Perhaps the most serious gap is when a firm’s written policies describe a program that doesn’t match what’s actually in place. The policy says quarterly vulnerability scans are conducted. The last scan was eighteen months ago. The policy says all third-party vendors are evaluated before onboarding. No formal vendor risk process exists. These mismatches are exactly what a thorough operational due diligence checklist is designed to surface.
The “Prove It” Gap
There’s a meaningful difference between claiming a control exists and being able to prove it. Experienced reviewers know how to ask for evidence, and they’re looking for more than verbal assurances.
Proof typically takes the form of screenshots showing tools are deployed, reports from monitoring systems, signed policy documents with review dates, training completion records, and backup verification logs. If a firm can’t produce this kind of evidence on request, the conversation shifts. The reviewer begins to wonder what else might not actually be in place.
Verbal ODD interviews add another layer of complexity. When a call is scheduled with a senior allocator or compliance team, the firm’s representatives need to be able to speak confidently about their security program without hedging or escalating to someone else mid-call. That level of fluency only comes from ongoing engagement with the program, not a last-minute review of a questionnaire. Partners like Altourage ensure you do not have to handle this process alone.